AuthSec
SPIFFE/SPIRE workload identity and M2M private_key_jwt — Stytch has neither
XAA supports genuine cross-org delegation; Stytch's On-Behalf-Of token exchange is scoped to a single user's own connected apps
Connector Broker is a shipped credential-injection product; Stytch's MCP guidance tells developers to build their own token store
Device Authorization Grant, CIBA, and PAR are all supported; Stytch documents none of the three